Japanese publisher Nikkei announced that unidentified attackers managed to access two employee email accounts in two separate incidents involving Google Workspace and Microsoft 365. The second account was used to send thousands of fraudulent messages to employees and people who had previously communicated with the company.
What happened?
In late July, the attackers gained access to an employee’s Google Workspace account. Nikkei said the incident may have exposed the names and email addresses of 1,646 employees and business partners, but confirmed that the affected data did not include information about readers or people it had interviewed.
The company received a notification from Google about the incident and discovered the breach in early August, then changed the account’s password. Nikkei did not specify how long the attackers had access to the account or whether the data was actually copied.
Microsoft 365 Account Turned into a Phishing Tool
In a more recent incident, attackers accessed another employee’s Microsoft 365 account during September. On September 30, the account was used to send emails to Nikkei employees and to people who had previously communicated with several of its staff members.
The messages contained links to malicious websites, and their number reached approximately 9,000. The company changed the passwords associated with the incident and said it had not detected any unauthorized logins since then. It also contacted the recipients individually and asked them to delete the messages.
Why does this matter?
The danger of corporate email account breaches is not limited to exposing data; a compromised account can be used to send seemingly trustworthy messages to colleagues, partners, and people who have a prior relationship with the employee. This increases the chances of phishing succeeding, particularly when the message comes from a known domain and relies on real contacts.
Nikkei warned affected people about new messages that may impersonate it or the names of its subsidiaries. The company did not attribute either attack to a specific entity or hacking group, nor did it confirm a connection between the two incidents.
A Recurring Security Context
The new disclosures come after other incidents announced by Nikkei in previous years. The previous year, its Slack platform was breached, affecting more than 17,000 employees and business partners. In May 2022, Nikkei’s Singapore company was hit by a ransomware attack targeting a server that was believed to contain customer data. Nikkei America also lost approximately $29 million in a business email compromise (BEC) fraud attack in September 2019.
Important questions remain open, including the nature of the data that may actually have been accessed, the precise duration of each breach, and whether the two incidents were connected. Therefore, the information published so far remains sufficient to confirm the two breaches and their initial effects, but it does not establish a complete criminal or technical scope of the attack.